Teams should attend together when they want shared context and a common set of contacts from the same event. Colleagues can divide conversations, compare notes afterward, and turn a social hour into a useful extension of the conference. That is especially helpful for teams that need alignment across architecture, IAM, and security operations.
Why This Matters for Security Teams
Identity conference social events are not just networking time. For security teams, they shape who gets shared context, who hears the same vendor claims, and who returns with a consistent view of identity risk. That matters in NHI-heavy environments, where misaligned assumptions about service accounts, secrets, and access paths can survive long after the event ends. NHI Mgmt Group notes that only 5.7% of organisations have full visibility into their service accounts in the Ultimate Guide to NHIs.
That is why attending together often makes sense for IAM, security operations, and architecture functions. The goal is not duplicating the same conversations. It is dividing coverage so the team can compare notes, test whether a product claim fits existing controls, and leave with a common language for follow-up. This is especially useful when evaluating guidance anchored in NIST SP 800-63 Digital Identity Guidelines alongside broader identity governance work. In practice, many teams only discover they attended a conference separately after they have already split their priorities and missed the same critical contacts.
How It Works in Practice
Teams should attend together when the event has limited time, dense vendor traffic, or multiple sessions that connect to the same decision. One person can focus on architecture questions, another on operations or incident response concerns, and another on roadmap fit. That reduces duplicate effort and creates a better readout for the rest of the organisation. The best outcome is a shared debrief, not three isolated impressions.
This approach works best when the team agrees in advance on what to collect: product claims, control mappings, implementation constraints, and any discussion of secrets handling or workload identity. For NHI-heavy topics, compare what vendors say against independent guidance such as the Top 10 NHI Issues and control expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls. That helps separate useful signal from polished messaging.
- Split attendance across relevant conversations, then regroup for a shared debrief.
- Assign one person to validate architecture fit and another to ask operational questions.
- Collect contact information for the same shortlist of peers, partners, and vendors.
- Capture any references to NHI governance, secrets rotation, and identity lifecycle gaps.
When teams attend together, they can also identify whether a new contact is better handled by an architect, an IAM lead, or a security operations manager. That reduces follow-up friction after the event and keeps decisions grounded in the organisation’s actual control model. These controls tend to break down when the event is highly social, the room is loud, and no one has pre-agreed note-taking or follow-up ownership.
Common Variations and Edge Cases
Tighter coordination often increases scheduling overhead, requiring organisations to balance coverage against the cost of pulling multiple people away from other sessions. If the conference is small, or if budget only allows one attendee, going separately may be unavoidable. The tradeoff is that separate attendance can widen perspective, but it usually weakens shared context unless the team commits to a structured debrief.
Best practice is evolving on how much overlap is enough. There is no universal standard for this yet. For some teams, two attendees are sufficient if one covers governance and the other covers operations. For larger identity programs, a broader mix may be useful when sessions touch on policy, integrations, or incident response. Where human identity guidance matters, it is still worth comparing event takeaways to ENISA Threat Landscape context and the lifecycle issues described in the 52 NHI Breaches Analysis.
If the conference is mostly about networking rather than technical depth, separate attendance may be more useful because it expands the team’s contact surface. But if the event is being used to evaluate identity platforms, NHI controls, or governance approaches, attending together usually produces better alignment and faster internal decision-making.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Shared event coverage supports better NHI visibility and ownership. |
| OWASP Agentic AI Top 10 | A-03 | Useful if the event covers autonomous agents and their identity needs. |
| CSA MAESTRO | MAESTRO-1 | Covers governance and coordination for identity-heavy AI and platform decisions. |
| NIST CSF 2.0 | GV.OV-01 | Conference takeaways should support governance oversight and shared priorities. |
| NIST AI RMF | GOVERN | Relevant when conference discussions include AI-enabled identity tooling. |
Assign attendees to gather NHI control gaps and return with a consolidated risk view.
Related resources from NHI Mgmt Group
- How should identity teams use an IAM event to improve governance maturity rather than just attend sessions?
- How should organisations secure privileged access, non-human identities, and secrets before an identity security conference or major programme rollout?
- Why do social media accounts used by public figures need stronger identity controls than ordinary consumer accounts?
- How should identity teams prioritise conference learning about agentic AI and machine identities?